Skip to main content
The short version

A subprocessor is a company we hire that ends up handling some of your data to do its job. Here is the whole list, split into the ones every account uses, the AI vendors, and the ones that only apply if you switch on a particular integration. We don't sell your data to anyone on this page, or to anyone else.

Always on

Core infrastructure

These are in the path for every account. Using Projlog means using these.

ProviderWhat they doWhat they receiveWhere
SupabaseDatabase, file storage, and authenticationAll Service data: accounts, project data, messages, photos, documents, sign-in credentialsUnited States
VercelApplication hosting and deliveryAll requests to the Service, including IP address and request metadataUnited States
StripePayment processing and subscription billingPayment card details, billing name and address, payment status. Card numbers go to Stripe directly and are never stored by usUnited States
ResendTransactional email deliveryEmail addresses, message subject and content, delivery eventsUnited States
TwilioText message and voice call deliveryPhone numbers, message content, call metadata, and call recordings where a Company enables themUnited States
SentryError and performance monitoringError reports, request metadata, and — on a sample of sessions where an error occurs — a replay of the page with text masked and images and video omittedUnited States
UpstashRate limitingIP addresses and account identifiers, held briefly to count requestsUnited States
CloudflarePublic asset delivery for map viewsIP address and browser data when a map loads its icons and stylesheetGlobal
Plausible AnalyticsWebsite analytics on our public marketing pages onlyAggregate page views. No cookies, no cross-site tracking, and it does not run inside the ServiceEuropean Union
BackblazeOff-site backup storage for uploaded filesEncrypted copies of photos and documents, written nightly. Files are encrypted on our side before they leave, so Backblaze cannot read themUnited States
GitHubRuns the nightly backup job that makes those copiesPhotos and documents pass through the backup job's runner briefly during each nightly run; nothing is stored thereUnited States
AI vendors

AI providers

These receive content only when someone uses a feature that is labeled as AI-assisted, or when a Company runs the prospecting tools. Section 07 of the privacy policy explains which features those are and exactly what gets sent.

ProviderWhat they doWhat they receiveWhere
AnthropicDrafting assistance (crew updates, end-of-day summaries), the staff assistant, and roof-condition assessment in the prospecting toolsThe text or image sent with a request. Not used to train their modelsUnited States
OpenAIFallback for the same drafting and assistant features, and speech-to-text for voice notes and dictationThe text sent with a request, and audio recordings when someone uses a voice feature. Not used to train their modelsUnited States
Opt-in

Optional integrations

None of these receive anything until a Company connects the integration in Settings. Disconnecting it stops the flow going forward.

ProviderWhat they doWhat they receiveWhere
GoogleSign in with Google, Calendar sync, Maps and Places lookups, Street View imagery, and Business Profile reviewsName, email, and profile ID at sign-in; calendar events; property addresses sent for lookup or imageryUnited States
MicrosoftSign in with MicrosoftName, email address, and profile identifierUnited States
Intuit (QuickBooks)Accounting syncCustomer names, invoices, payments, and line itemsUnited States
ZoomVideo consultationsMeeting scheduling details and participant email addressesUnited States
MailchimpMarketing email, for Companies that connect their own accountContact names and email addresses the Company chooses to syncUnited States
EagleView, GAF QuickMeasure, RoofrAerial roof measurement reportsProperty addresses and the resulting measurement reportsUnited States
ABC Supply, SRS Distribution, BeaconMaterial catalog and orderingOrder contents and job-site delivery addressesUnited States
Tomorrow.ioWeather forecasts for scheduling and daily reportsJob-site coordinates or postal codesUnited States
Apollo.io, Hunter.ioBusiness contact lookup in the prospecting toolsCompany names and business contact details submitted for lookup. See the note belowUnited States
RegridProperty parcel and ownership records in the prospecting toolsProperty addresses and parcel identifiers. See the note belowUnited States
Note

A note about the prospecting tools

The prospecting tools differ from the rest of Projlog in one important way: they process information about property owners who are not our users and have no relationship with us. A Company using those tools chooses whose property to look up, and is the controller of that information and responsible for having a lawful basis to process it. We are the processor. Section 07 of the privacy policy describes what the tools do, and any property owner can write to privacy@projlog.app to ask what we hold about a property and to have it deleted.

Changes

When this list changes

We update this page when we add or remove a subprocessor, and Companies can ask to be notified of changes in advance by writing to privacy@projlog.app. If you have a data processing agreement with us, the notice terms in that agreement control.

↑ Back to top